#FactCheck: AI-Generated Video Falsely Shared as Footage of Landslide in Nepal
Executive Summary
A video is being shared on social media showing a large amount of debris cascading down a mountain amid multi-storey buildings. The video is being shared with the claim that it shows a landslide incident in Nepal. CyberPeace Research found the viral claim to be false. Our research found that the viral video is AI-generated and is being shared with a misleading claim.
Claim:
A Facebook user shared the viral video on September 29, 2026, with the caption, “A horrifying scene of a mountain collapsing in Nepal.” The post link, archive link and screenshot are provided below.
https://x.com/ptravidwivedi/status/2104934750595219494

Fact Check
To verify the authenticity of the viral claim, we conducted a reverse image search using keyframes from the video. However, we did not find any credible media reports or other reliable sources related to the video during the search. Upon closely examining the viral video, we noticed several inconsistencies that raised suspicions that the video may be AI-generated.

As part of the next step in our research, we scanned the video using the AI detection tool Hive Detect. According to the results, the viral video has an 83 per cent likelihood of being AI-generated.

At the end of our research, we scanned the viral video using the AI detection tool WasIt AI. According to the results, the viral video was found to be AI-generated.


Conclusion
Our research found that the viral video is AI-generated and is being shared with a misleading claim.
Related Blogs

Introduction
The recent advisory issued by CERT, issued on April 26th, 2026, titled “Defending Against Frontier AI-Driven Cyber Risks”, on AI-driven cyber threats does not merely add to the list of routine cybersecurity warnings. Instead, it marks a shift in how cyber risk itself is understood. The concern, here, is not just that attacks are increasing, but also that their nature is changing. Artificial intelligence is no longer assisting cyber operations- whether legitimate or malicious, in fragments; it is beginning to organise and execute them at scale.
What is emerging is a situation where capability is no longer tied to human skill alone. Systems can now identify vulnerabilities, generate exploits, and carry out coordinated attacks with limited intervention. This alters the baseline assumption of cybersecurity, that attacks require effort, time, and expertise.
The Essence: Automation and Capability
At the core of the advisory lies the recognition that AI has introduced speed and autonomy into cyber operations. Tasks such as analysing code, identifying vulnerabilities, or crafting phishing content are no longer sequential processes. They can happen almost simultaneously and at scale.
This is not simply a matter of efficiency. It changes the structure of the threat itself. When attacks can be automated, they become repeatable and less dependent on specialised actors. The advisory also points to the ability of AI systems to conduct multi-stage attacks, moving across networks and adapting strategies in real time.
In a way, the threat is no longer just external. It is embedded within the logics of the technology being used.
Significance: Lower Barriers, Wider Exposure
One of the more important aspects of the advisory is its emphasis on ‘accessibility’. AI lowers the barrier of complexity in the commission of cybercrimes. Activities that once required coordinated teams can now be performed by individuals with access to advanced tools.
This has two consequences. First, the number of potential attackers increases. Second, the scale at which attacks can be carried out expands significantly. Systems that were previously considered low risk may become viable targets simply because automated tools can scan, test, and exploit them rapidly.
There is also a broader anxiety reflected in what is being described as “Mythos concerns”, a shorthand for uncertainty around frontier AI systems and their unpredictable capabilities. This signals that the risk is not fully mapped yet and that regulatory responses are still catching up.
Element of Continuous Risk
The advisory outlines impacts such as unauthorised access, data breaches, identity theft, and financial fraud. These are familiar categories. What is less explicit, but more important, is the shift in how these harms occur.
When AI enables rapid and repeated exploitation, risk becomes continuous. Systems are not attacked once and then secured. They are exposed to ongoing attempts. This creates pressure not only on technical infrastructure but also on legal frameworks that are designed around discrete incidents.
For instance, obligations under the Information Technology Act, 2000 or even emerging data protection frameworks often assume identifiable breaches and reportable events. Continuous probing complicates that model!
Response Framework: From Compliance to Vigilance
CERT-In’s recommendations reflect this change in threat perception. There is a clear emphasis on vigilance rather than mere compliance. Organisations are advised to adopt zero-trust approaches, reduce exposure surfaces, and treat vulnerabilities as immediately exploitable.
The insistence on rapid patching within short timeframes is particularly telling. It acknowledges that the window between vulnerability disclosure and exploitation is shrinking.
There is also a noticeable expansion of responsibility. The advisory does not limit itself to large organisations. It extends guidance to the MSMEs and individuals, recognising that cyber risk is now distributed across the entire digital ecosystem.
A Subtle Legal Shift
Although the advisory itself is not binding in law, it operates within the framework of Section 70B of the Information Technology Act, 2000, which empowers CERT-In to issue directions on cybersecurity best practices and guidelines.
So, while the advisory does not create liability directly, it influences what may later be considered ‘reasonable security practice’. In that sense, it serves as soft law, gradually informing standards of due diligence.
At the same time, there remains a gap. The advisory focuses on defensive measures, but it does not fully address attribution and accountability in AI driven attacks. When actions are automated and anonymised, identifying responsibility and imposing liability becomes more complex.
Conclusion
The CERT In advisory is not just a warning about new threats. It is an acknowledgement of a transition. Cyber risk is moving from being occasional and targeted to being constant and scalable. AI is not simply adding to existing threats; it is restructuring and advancing them.
For cyber vigilance frameworks, this suggests a need to rethink priorities. Static compliance measures are no longer sufficient. It has become necessary to adopt continuous monitoring, adaptive responses, and a clearer understanding of how technology is reshaping risk.
While the advisory does not resolve these questions, it does bring them into focus. And that, in itself, is significant.
References
- CERT-In issues advisory against AI driven cyber attacks for MSMEs, organisations and individuals, Moneycontrol (Apr. 27, 2026), https://www.moneycontrol.com/technology/cert-in-issues-advisory-against-ai-driven-cyber-attacks-for-msmes-organisations-and-individuals-article-13899942.html.
- CERT-In warns of rising AI driven cyber threats amid Mythos concerns, Ommcom News (2026), https://ommcomnews.com/science-tech/cert-in-warns-of-rising-ai-driven-cyber-threats-amid-mythos-concerns/.
- Indian Computer Emergency Response Team (CERT-In), Defending Against Frontier AI Driven Cyber Risks, Advisory No. CIAD-2026-0020 (Apr. 26, 2026)
- Information Technology Act, 2000, § 70B (India).

Executive Summary
A disturbing video showing a man assaulting a bhelpuri vendor is being widely shared on social media. In the video, a man approaches the bhelpuri vendor, eats bhelpuri from his basket, spits on him and appears to assault him. Social media users are sharing the video claiming that it is from Patna and are demanding action against the man seen behaving indecently. CyberPeace Research Wing’s Research found that the video is scripted. It is being shared on social media with a misleading claim.
Claim:
A social media user shared the viral video with the caption: “A video has surfaced showing the alleged mistreatment of a young man selling bhelpuri at Patna Junction railway station. It is alleged that some people misbehaved with the vendor after eating bhelpuri and put bhelpuri into his mouth. Why should a poor, hardworking person be treated this way? The Bihar government and the concerned railway authorities should investigate the video and take appropriate action. Samrat Choudhary ji, please also look into this incident reported at Patna railway station.”
https://www.facebook.com/reel/29198229276436585

Fact Check
To verify the truth behind the video being shared with the claim that a bhelpuri vendor was assaulted, we conducted a reverse image search of its keyframes. During the search, we found a video uploaded on September 18 on the Facebook account of a user identified as Sonu Paswan. The person seen assaulting the vendor in the viral clip can also be seen in this video. In the video, he explains that the viral clip was scripted and was recorded solely for entertainment purposes. He appeals to people not to take the video seriously or share it further. He also says that after the video went viral, he had to delete several videos, due to which much of his effort went to waste.
https://www.facebook.com/reel/2161698368111775

Additionally, upon examining Sonu Paswan’s Facebook account, we found several other videos in which the same two men seen in the viral video can be seen acting together in different situations.

Additionally, we found a video uploaded on Sonu Paswan’s Instagram account on September 18. In the video, he explains that the person selling bhelpuri/bhujia in the viral clip is Sonu Kumar, while the person seen assaulting him is a member of their team. Sonu Kumar says in the video that they work together to create videos on poverty and emotional issues. He also appeals to people to watch the viral clip as entertainment and not share it further. This makes it clear that the viral video is scripted.
https://www.instagram.com/p/Dda41TdzMxO/

Conclusion
Our Research found that the video being shared with the claim that a bhelpuri vendor was assaulted and mistreated at Patna railway station is scripted.

Executive Summary
A video showing a massive fire with thick black smoke is being widely shared on social media with the claim that it depicts a recent Israeli attack on Iran. CyberPeace Research Wing research found that the claim is false. The viral video is not related to Iran or any Israel-Iran conflict. It actually shows a gas pipeline fire in Kizilyurt city of Russia’s Dagestan region.
Claim:
A video circulating on X shows a large fire breaking out at a location with thick black smoke rising. The clip is being shared with a caption claiming, “Israel has carried out more than 500 surgical strikes on Iran in the last 24 hours.” Post link: https://x.com/ocjain4/status/2064700017361985702, https://x.com/ocjain4/status/2064700017361985702

Fact Check:
A reverse image search using keyframes from the viral video led to visuals published in a report on a Dagestan-based media outlet dated June 9. The report stated that the Russian Emergency Situations Ministry’s Dagestan department received reports of three explosions at a methane gas station.
https://riadagestan.ru/news/incidents/v_dagestane_vzorvalas_azs

Further research found that several Russian media outlets also published the same visuals on June 9, describing them as a pipeline explosion and fire in Kizilyurt, Dagestan

We also found a report published by DW on June 9, 2026, which stated that three explosions occurred on the Mozdok–Kazimagomed gas pipeline in Kizilyurt, Dagestan, resulting in a massive fire with flames rising up to 15 meters. According to local authorities, no casualties or injuries were reported..
https://www.dw.com/ru/na-gazoprovode-v-dagestane-progremeli-tri-vzryva-voznik-pozar/a-77481599

Conclusion:
The research clearly shows that the viral video is unrelated to the Israel-Iran conflict. It actually depicts a gas pipeline fire in Russia’s Dagestan region, which has been falsely shared as a recent Israeli strike on Iran.